Grant Gross
Senior Writer

GAO report knocks FAA info security efforts

News
Sep 29, 20053 mins

The U.S. Federal Aviation Administration lacks security controls for its IT networks and in some cases hasn’t installed software patches that are several years old, according to a report made public Monday by the U.S. Government Accountability Office.

FAA’s lack of controls on network security as well as on passwords, user accounts and user privileges could “lead to disruption in aviation operations,” the GAO report said. The FAA had not installed patches released in 2002 on some of its servers, and it has permitted “excessive access” to air traffic control systems by granting permissions that allowed more access than users needed to do their jobs, according to the GAO.

The FAA said the GAO’s findings do not reflect the overall security of FAA systems such as air traffic control. The GAO examined only three of the FAA’s 80 information systems, said FAA spokesman Greg Martin. “We have a very secure system,” he said.

FAA has established an extensive security training program, deployed intrusion detection systems and established a cybersecurity incident response center, FAA officials told GAO. GAO conducted the security review between March 2004 and June 2005, at the request of two congressmen.

The GAO report failed to look at FAA’s “multiple redundant systems” and special access protocols built in to FAA’s IT infrastructure, Martin added, mirroring comments in the report from FAA CIO Dan Mehan’s office. Asked about unpatched systems, Martin said the FAA has used a “risk-based” approach to patch the most important vulnerabilities.

FAA will consider GAO’s recommendations, Martin said. “It’s important to note that as we go about implementing a systemwide security program, we’re not going to go in quickly and install systems for the sake of meeting some schedule, but rather, do it very carefully, do it very deliberately,” he said. “We don’t want patches to have unintended, adverse consequences.”

FAA officials told GAO that the possibility for attacks was limited because their systems are partially custom built and run on older equipment that uses special-purpose operating systems and custom-built software. “Nevertheless, the proprietary features of these systems cannot fully protect them from attacks by disgruntled current or former employees who are familiar with these features, nor will they keep out more sophisticated hackers,” GAO said.

Among the GAO criticisms:

* The agency did not consistently install patches in a “timely manner.” GAO found an outdated, unpatched 1991 operating system running on one FAA system, it said.

* FAA did not consistently configure network services and devices to prevent unauthorized access.

* Software the GAO reviewed had “several weaknesses” that could lead to attacks.

* FAA did not encrypt some information being sent on its internal network.

* FAA did not comply with federal standards for handling security certificates and keys.

* The agency did not maintain adequate controls over user accounts and passwords, and one database did not require strong passwords.

* FAA permitted “excessive access” to air traffic control systems by employees who did not need access.

* FAA had several inadequate physical security controls, including inconsistent controls of employee badges and inconsistent screening of visitors to FAA facilities.

FAA has “not yet fully implemented an information security program to ensure that effective controls are established and maintained,” the GAO report said. “Although FAA has initiatives under way to address these areas, further efforts are needed to fully implement them.”

Grant Gross

Grant Gross, a senior writer at CIO, is a long-time IT journalist who has focused on AI, enterprise technology, and tech policy. He previously served as Washington, D.C., correspondent and later senior editor at IDG News Service. Earlier in his career, he was managing editor at Linux.com and news editor at tech careers site Techies.com. As a tech policy expert, he has appeared on C-SPAN and the giant NTN24 Spanish-language cable news network. In the distant past, he worked as a reporter and editor at newspapers in Minnesota and the Dakotas. A finalist for Best Range of Work by a Single Author for both the Eddie Awards and the Neal Awards, Grant was recently recognized with an ASBPE Regional Silver award for his article “Agentic AI: Decisive, operational AI arrives in business.”

More from this author